I don't think this is a moral/ethical issue--everyone agrees that the frontier labs are responsible for hacking attempts. No one is trying to deflect blame.
Instead, this is a legal question: What were the damages? Was the target company negligent in setting up security? Were criminal laws broken? Etc. [IANAL, so forgive the lack of precision.]
If hacked companies had losses, they have an incentive (even a fiduciary duty) to recoup their losses. They do that by suing the company (as, e.g., authors sued Anthropic for copyright infringement). If they haven't sued the company, it means either (a) they didn't have losses, or (b) they're still working on the lawsuit and haven't filed it yet.
The other dynamic is that frontier labs feel competitive pressure to take risks to develop their models. Which risk is higher:
A. A new model being tested hacks into a sensitive site (bank, government, etc.) and the company has to pay a massive fine (or even face jail time).
B. A competitor comes out with a significantly better model and they lose significant market share.
That is a hard choice to make. The frontier labs are asking for government restrictions--that apply to all companies--so that they can minimize A without having to worry about B.
They are trying to minimize their risk (and thus maximize their profits).
It's not so much that it can't make a decision, but that whoever allowed it to make decisions is ultimately responsible for them.
Decision laundering is a great term. There is ultimately a human who gave the program free rein. You can't say "sorry my car hit you, it's not my fault" especially when the person driving works for the car manufacturer too.
Which also seems to be in line with the way the frontier labs gathered and used copyrighted data to train their models
And even before AI, limited liability corporations (like LLCs or C corps), also have the intention of protecting the individuals from the repercussions of their actions
In a way this could be generalized as “accountability laundering”. Making someone unaccountable for their actions, by redirecting the responsibility of those actions, to a non-punishable entity (like a C corp or “a computer”)
The question isn’t who or what made the decision, per se. It’s who is responsible for the outcome. The entity making the decision might be the actual cause but not the proximate cause (the cause most closely connected to legal liability) for the harm that occurred.
Except now there's no longer any guarantees there's even any people you can point at. It's already often diffuse responsbilitiy. Maybe today you can still sort of get around that by pointing at business/organization owners. But soon we're going to see situations where that isn't even realistic. For example if AI agents start spinning up their own agents which work outside of the control of anyone. We're going to need some way to deal with that.
Agents run on computers, those computers have owners. We have to maintain accountability and not let people who stand to get rich from privatizing the profits but socializing the risk of rogue agents from continuing to push a narrative of autonomous super intelligence that is “too powerful” to control.
That narrative is bullshit. Intelligence is not power. The power comes from hooking these agents up to everything without proper safety controls. The fact that those safety controls don’t exist yet is not humanity’s problem, it’s the frontier labs problem, and we can’t let them wriggle out of it with an Overton window shift or demanding that the government take responsibility via regulation (of course they should but it doesn’t absolve the labs of responsibility for their own actions).
Why would that need a new way? Or do you mean that no-one ever spun up anything at all (e.g., agent zero was never spun up or allowed to be spun up by anyone)?
corporations are legal persons, and they can make decisions that negatively effect society as a whole, yet often no single person in the corporations is responsible and each individual may not even see themselves as morally responsible
Well that’s because they are legal fictions and often run by morally bankrupt individuals. The people making the decisions are still responsible for them.
Don’t confuse lack of accountability with lack of responsibility.
Yes. You can have some free will without having absolute free will.
For example, I can decide which cereal to purchase at the supermarket. But I cannot decide which cereals are offered to me at the supermarket. The supermarket has allowed/enabled to make a constrained decision.
I wonder if theres an approach to getting an arbitrary grocery store or even like an arbitrary pizza chain to offer your favorite dressing/dip, id love to see my fave become more popular/normalized
> You can have some free will without having absolute free will.
So does it follow then that the agents in question do have "some" free* will? I'm not sure you realize what conclusion naturally follows from this, and how it contradicts the point made in the article and the top-level comment I replied to.
(*) My earlier question wasn't explicitly about free will but we'll go with it.
Personally I don’t agree with the article that computers cannot make decisions (or at least, I don’t think the article made any case why I should agree with the statement).
While I agree that computers cannot currently be held accountable for decisions (because I do not think they have free will), I think it’s transparently clear that computers make decisions all the time, and have done since they were first implemented.
OK, but one of the examples in the source article was a report from third-party testing of those safeguards. I feel like you're starting from an unexplored presumption that adequate safeguards must be easy to build and anyone who doesn't build them is just being lazy.
> Inadequate or broken safeguards do not fall under my definition of reasonable.
I see no such assumption there. In my reading, the implicit assumption is that adequate safeguards are necessary and that anyone who doesn’t build them is irresponsible. And I feel that that is correct.
AI is irresponsible technology, because we have no idea how it works or how to contain it. It's worse than writing code that suffers from SQL injection vulnerabilities because at least in that case we know how to fix it.
The AI labs say "AI can make mistakes". That's why the responsibility of using it is on you. This may change if we get more legislation. But given the argument above, it will probably never shift to the AI itself having any responsibility. Instead the AI labs can be responsible.
"AI can make mistakes" continues to be the fundamental problem.
It's like having an assistant that can be helpful, but not always. We can bicker about the ratio of helpful to unhelpful interactions, but there will be some unhelpful moments.
And hoo boy, those can range from "eh, whatever" to being like a deranged toddler just got its hands on whatever tools and permissions were granted to the "mostly helpful" assistant.
And we can't get rid of that chance. We can pare it down a bit. But we can't get rid of it because it is fundamental to how the technology works.
That's fundamental to how _any_ technology works. If the bar for use is "can never go wrong ever", then you need to throw away every human invention ever made.
The problem is the scope of errors is so wide. It's not reasonable to compare LLM style failures to other technology failures. These 'failures' are not actually failures, they're part of the normal operation of the system.
It's like a vending machine that 99% of the time it dispenses tasty snacks, but 1% of the time it gives you poison that appears to be normal, unexpired product. It just does this. They did their best to minimize how often it happens, but the poison chance is still there. It can't be removed. It's part of the system.
A "normal" vending machine has failure conditions, sure. They generally can't do worse than cause you to lose your money without giving you a product.
Outlook 2003 never presented a risk of draining my bank account to buy memecoins because a spam email was treated as instructions.
Computers can make decisions: Almost everyone reading this will have a implemented an if-else statement or equivalent control flow. That is a decision made by a computer on data it receives at runtime. You can argue that it's different, because we fully understand the logic of such a statement, whereas LLMs are closer to a black-box. But at Turing observed, in practice we are frequently surprised by the output of complex algorithms, even those we have authored ourselves. The more difficult the task, the more complex the algorithm we need to achieve it, and the more unexpected behaviour can emerge from it. In that way, LLMs are just the latest, highest point on a rising line of algorithmic capability and complexity.
We can (and should) try to improve AI safety and alignment, but perfect safety is probably impossible without losing the capabilities that make AI unique. Black-and-white positions that insist anyone creating or using an AI is responsible for anything it does wrong under any circumstances are also unrealistic. AI is a general purpose technology, and we have always accepted that it is not practical for suppliers to envisage and constrain every downstream use: Car manufacturers cannot prevent every instance of mechanical failure, nor can they stop cars being used in crime.
I disagree. Computers cannot make judgemental decisions about course of action, they can only execute predefined courses of action. The software developer made a series of decisions. The computer just carried those out.
These discussions around decision-making seem to ignore what a "decision" is. How does a human being make a decision? And what exactly is happening when a person decides to do something?
Suppose I check the weather forecast 5 mins before leaving the house, and it says 95% chance of rain today. Do I bring or not bring an umbrella?
I would bring an umbrella. I would made that decision to bring an umbrella. But my decision to do that is (at least partially) the result of the weather forecast. The causal chain is (atmospheric conditions -> weather forecasters -> my decision). Did the weather forecaster just "program" me? Did the water molecules moving in the sky just "program" the weather forecaster?
My answer to these questions is as follows: a decision, and my understanding of the concept/definition of a "decision", refers to exactly the processes where I do something as a result of external influence/programming, rather than just internal thought/processing. I could think really hard and imagine myself moving forward at 100 meters per second, or even beyond the speed of light, but in reality, no matter how hard my neurons fire to imagine that scenario, my actions are still physically constrained. Such physical constraints influence our every decision. That is the "programming" part. Everyone and everything "programs"/influences everything else.
That said, perhaps the particles which make up my brain/body has its own whimsy. Perhaps there is a hidden local random number generator that samples from the distribution of possible future states available to this particular clump of matter that is "I".
How different is this from a computer running a non-deterministic program such as an LLM-based AI agent? Remember, every token sampling involves an RNG. They don't perform as well or feel as creative and human-like when deterministically sampled.
This isn't an excuse for anyone, especially not for Anthropic or OpenAI. But I think these are questions we ought to ask if we are to honestly discuss liability and perhaps even personhood for AIs that are increasingly autonomous.
> they can only execute predefined courses of action.
Even in near trivial cases such as Game Of Life (just a handful of rules), the fact that a <machine> technically carries out deterministic actions is already quite meaningless.
To determine by mathematics, especially by numerical methods: synonym: calculate.
"computed the tax due."
decide /dĭ-sīd′/
intransitive verb
To reach a conclusion or form a judgment or opinion about (something) by reasoning or consideration.
"decide what to do."
I would agree.
The programmer, architect, CIO, engineer, etc. made the decisions, reached the conclusions, reasoned about the problem.
In the case of an AI vibe coder, the collective published works of said programmers, architects, CIO, engineer, etcs reasoning was applied to the vibe coders question, itself a result of reasoning. AI is still just calculating.
Digital computers ( the ones I assume we are talking about ) are turing machines.
The original article feeds precisely this misreading. It quotes the old IBM adage ‘a computer MUST never make management decisions’ (my emphasis) but describes it in its headline as ‘a computer CAN not make decisions’ (my emphasis)
These are not the same, and this misinterpretation of the author’s intent inevitably follows.
CAN NOT is horribly ambiguous in English which is why RFCs use MUST and MAY.
In casual speech someone might say “you can’t park there” but that’s not true. They might mean “you must not park there” or “you should not park there” but the only reason they are telling you is because you CAN park there.
More to the point, a simple control flow statement is really a decision made by the person who programmed the computer, not made by the computer.
Though LLMs make this all fuzzy it's still basically the same thing. LLMs didn't decide to make a toxic culture of LLM use, people did. They were told that it was necessary to save themselves.
Yet decisions are still made by abstract entities such as "companies" and not the individuals working for them. So that blame can be diluted and deflected in a very convenient manner for CEOs. Just find someone to fire, but keep doing the same thing.
Instead of "Anthropic submits false tip to police", I'd prefer "Anthropic employee John Smith deploys an agent that submits false tip to police". Of course, John Smith will be able to then say "I did so as ordered by my superior, Ms Sue", and so on, with a very clearly established chain of liability.
A corporation and an AI are not very different in many aspects, except one of them is very favourably treated by law, almost as a living person.
There is an agreed legal mechanism for distributing this responsibility - limited liability. Now, we might not like this, but it is what our society came to (it could be undone, but it hasn't been). AI models do not fall into this chain of liability any more than guns do (IMO). So the output should be:
"Anthropic employee John Smith [killed the children with the gun||launched a cyber attack] because he was ordered to by his superior and [has all the blame because such orders are null || we agree that Anthropic can order children to be killed]"
I love the term "decision laundering", but this is describing a classic poor management trope.
A bad manager takes personal credit when things go well and finds a scapegoat when things go bad. A good manager gives credit when things go well and takes responsibility when things go bad.
It's wrong to scapegoat the agent. You, the human who executed the agent, made the decision to execute it. You gave it credentials, and set up insufficient guardrails. Don't scapegoat the agent for your poor decisions.
Likewise, it's good to have humility when you get great results out of agents. Yes, the agent made the good results happen. It's OK to tell people that your choice of agent is amazing and did an incredible job. In any half-decent work culture, that should rub off on you as well.
I like what you said about good managers. A good manager sets their reports up to win and ensures those reports get the credit, because the manager's job is to enable career progression of their reports.
That's not the situation here. We aren't enabling the career progression of software which does matrix multiplications.
Accountability of us schmucks at the end of the org chart goes both ways. We get some reward when we do it right, and we improve when we do it wrong.
A reward might be something tangible or might be as small as your own personal satisfaction.
An improvement is hopefully identifying what went wrong and doing better next time, and in extreme cases your employer will let you try again at a different workplace.
The question of whether it's better to frame a reaction to issues in a positive, do-better-next-time or a negative, don't-do-that-again way (fwiw, I agree that the positive way is better) is orthogonal to the argument I was trying to make about who is the recipient of that reaction. Scapegoating the agent is farcical. Clearly, "make no mistakes" style prompts are a poor approach to agentic development.
> the manager's job is to enable career progression of their reports... we aren't enabling the career progression of [fancy calculators]
While I do agree that good human managers concern themselves with career development of their human direct reports, I disagree that it's a fundamental part of the job description. The foundation is for a manager to get and keep their reports being productive. Human workers are often concerned with career progression, so good managers concern themselves with such career progression as well. Agents are not, but that doesn't mean that lauding good agentic work is meaningless. Lauding the work is also valuable for: (a) reinforcing a culture of positivity and celebration, which rubs off on human workers as well, (b) part of a culture of continuous evaluation of agents and models - asking questions like, are there cheaper or faster models that would be just as effective?
It's interesting how this relates the classic problem of "responsibility vs authority".
Humans, especially ones under abusive managers, often have a lot of responsibility but no authority that affects the outcome.
In an ideal situation you either have both, or none. You make the decision and answer for it, or you follow decisions but don't get blamed when it's wrong.
LLMs managed to slide into a space where they get to make authoritative decisions but if something fails we don't really blame them.
I'm not saying LLMs should be held responsible, but it's funny how people claim they replace humans, but are giving them an extremely easy, kid-gloves, success target.
I would go farther and argue that companies don't make decisions either. They are also not people (legal nonsense notwithstanding). Individual actual humans make decisions and they're the ones who should be held accountable.
I think that when there are not explicitly stated attribution of liability for decisions that are at the core of a problem the general rule should be that the accountability should be proportional to the additional benefit that each agent or person receives for that decision. That rule is in the context that each agent is responsible to read information and communicate to others in the chain about the risks that decisions entails. The overall structure of an organization should have the goal of making such information about risk available for all agents in the chain in a way that the amount of information can be digested by the agents without much problems.
Through what mechanism are they accountable for that if not corporate liability? If I pay a taxi driver to take me home from the airport, and he hurts someone by driving in a negligent way, I'm not accountable for delegating my driving decisions.
You just have to say that you need dedicated figures for some decisions, like you already need for GDPR or financial compliance or certifications, and ultimate responsibility is always of the ceo.
...like it already happens in europe, or at least in Italy.
This is basic law and risk management in society. Let's not pretend we have just invented corporations and don't know what to do with them yet.
Of course the modern company (legal nonsense withstanding) exists specifically to limit that ability to hold any people accountable for the actions of their company.
And I would go farther and argue that governments do not make decisions either.
Oh, wait, that was a core concept from "Mein Kampf": parliament are bad because nobody is responsable, hence nobody care about doing the right thing ! (probably the only concept from that book that I can agree to)
Yeah, when someone is literally a Nazi (I hope in 2026 we can all agree that at least Hitler was one), it's not really surprising that they would prefer a dictatorship over a parliament full of elected people.
Over the year, "a parliament full of elected people" has lost more and more of its meaning (with regard to original intent)
Regardless, this is less about dictatorship and more about personal responsibility and accountability
A solution, perhaps, would be to ensure that such decisions are not anonymous and that, if the decisions had bad consequences, then the related people would be accountable
Of course, this would make the politic business less attractive. Would that be a bad idea ?
Yes, but I'd say there is also responsibility attached to the deployment and use (be that, e.g., for quant fund performance, behaviour on exchanges, ...). In a way, using an algorithm is the decision humans make that matters.
At the same time, I've been involved in hundreds of After Action Reviews of incidents and it's not always simple or easy to both figure out which party was ultimately responsible and also how to allocate the "dollar error budget" to the parties overall.
I fully agree that companies are doing this, not their "agents", and that companies are responsible for the damages they do.
But I don't think the average person with their $20 subscription to whoever is the primary source of revenue. Enterprises fund most of it by buying API keys and making those fancy chatbot buttons on their sites that nobody clicks, as well as some internal business automations if I had to guess.
If it was just average people with $20 subscriptions funding all this (keep in mind, most people using AI services do not pay for it), by now, all these AI companies would have gone bankrupt.
Except enterprises aren't funding it with API usage either.
These businesses lose unbelievably large amounts of investor money. Their AI-related revenues don't get even close to paying for their AI-related outlays.
End user (invididual, small business, large business) clients are still complicit not because they are funding it, but because they are signalling to investors that this is something people/businesses want.
Nobody gets off the hook here. It is every bit as much end user nihilism as it is AI company nihilism.
Your end users are divided into multiple categories though.
AI spending is a bit like Pokemon games - most of your players are free to play, only earning you traffic and maybe some more players after recommending it to their friends - that's the average AI user. Around 5-10% of players pay a bit to the game - maybe to unlock some extra characters - those are the $20-$200 AI subscription users, with these you are not going to fund the whole business but it's some side cash. Then you have the 1℅, which spend massive amounts of money onto the game, and those are the ones primarily funding it - that's the business spending and where most of the money actually comes from.
You can only blame the average person for using the cloud service and recommending it to others.
>End user (invididual, small business, large business) clients are ... complicit ... because they are signalling to investors that this is something people/businesses want
Erm, you appear to have missed the last 100+ years of updates to Western Capitalism.
People don't want it, you make the demand with hundreds of millions of spend on advertising (brainwashing), influencers, and social proof.
The capital holders don't sit back and see which company wins so capital can be directed to the best solutions, they buy up the competition, they pay corrupt politicians, they use current v market placement to embed their products name into billions of workplace computers and spread stories about how it's going to 'increase productivity but never at the cost of jobs', etc.
Yes, ultimately a dollar is a vote, but I don't think you can blame the people being manipulated "every bit as much" as those controlling the manipulation to feed their avarice and/or megalomania.
> Erm, you appear to have missed the last 100+ years of updates to Western Capitalism.
Not really.
> Yes, ultimately a dollar is a vote, but I don't think you can blame the people being manipulated "every bit as much" as those controlling the manipulation to feed their avarice and/or megalomania.
Oh but I do.
Collective social guilt is a thing. e.g. who is to blame for drug violence? Not only drug dealers.
I think we know today that blaming everyone and their plant doesn’t actually solve the problem. The formula that does is: find the ultimate beneficiaries (shareholders) and make them lose a lot of money to, then their delegates (CEOs) and punish them with jail time. There are lots of opinions about this, but I don’t see how this does not work.
It doesn't work because the people who are supposed to be leading us are on the payroll - sometimes actually - of the shareholders and CEOs, or are in fact in that same group.
If you brought down prod and deleted customer data and told them Claude did it, you’d still be the one in trouble. So they do know how to hold people accountable for actions taken by AI.
Has this actually been put to the test yet? If a company has officially sanctioned, or maybe even encouraged, AI agent usage I'm not sure the employee can be held completely accountable. I doubt any of these companies are providing training of any kind. It would be like if a factory suddenly replaced all the machines with ones without safety features and said "well, it's your fault if you kill yourself or your workmates".
Computers can make decisions and they do it all the time.
The problem is entirely different. Sometimes they make decisions we don't like, but unlike with people we haven't found a way to punish them that satisfies our sense of justice or discourages other computers from making similar decisions.
Decisions in the sense of defined branching, yes. The existence of prior and potential branches are necessary to be defined (branches cannot be 'invented'). This is unlike humans, who can form decisions by all manner of means / wants (by deception being the most striking I would wager).
Even in the LLM age, the existence of branching - prior art, or context, or prompt, the result of a prior branch - is necessary, no matter how hard the marketing might cloud this.
I have no clue why people are so confused about any of this: The owner makes the decision, or pays a CEO/politician to make the decision. Owner is somebody vested with that right, for not particular reason. Could be ownership through capital. Could be voting rights in a country. Could be the son of a king.
It does not matter if the CEO is an AI or a human. In either case, of course they can make decisions -- and be held responsible. Not in any emotional sense (that we seem to want to bake into the concept for added confusion), just that if you are not satisfied with the result, you can replace the human or AI.
I am not saying that this is a fun vision of anything, but why are we making it more complicated than it is? The parts are all there and explained.
> emotional sense (that we seem to want to bake into the concept for added confusion)
My understanding is that 'emotional' sense emerged organically in LLMs and was not intentionally baked in.
As silly as it may seem, the ways emotions come through in our words do seem to have an effect on agents. Likely because they were trained on human writing, most of which cannot be separated from the emotions of the writers any more than your emotions can be separated from your logic & reasoning abilities.
What is a chess computer doing, if not making decisions on what move to play?
While it seems reasonable that you need humans to take accountability, it looks like a very shaky position to assert that computers can't make decisions. And going back to chess computers, we acknowledge that computers make better decisions than humans in that area.
Forbidding computers that can make better decisions than humans from making decisions to keep accountability just seems to be arguing to hire fall guys. You still want the better decision maker to make decisions, but you need someone there to take the fall if things go wrong.
games are different from reality and chess computer(Deterministic) is bounded by set of rules and restrictions. Where as an AI agent (stochastic) sometime can't with held its guardrails since it specifically awoken using specific terms but we can trick the agent here (but currently the agents are becoming resilient).
Has any of the targetted organizations (e.g the Australian government) engaged in legal actions against Anthropic/OpenAI? If not then I'm afraid the situation won't change. Even worse it could send the wrong signal that there is a "legal blur" around this topic.
Ironically this piece makes the same type of error that it is criticizing!
The piece: "Anthropic COULD stop their models from doing what they are doing, and they are actively choosing not to"
As if _Anthropic_ could make a decision.
Companies cannot make decisions! All of these incidents are the fault of people. Companies are not deciding to do this, people are. There is little more to it than that.
Some might argue that humans (or any other species) cannot make decisions either and that the process is simply more evident in simpler scenarios, like computers.
I was thinking if you release an AI agent and it does bad stuff and you are responsible then by analogy if you have kids and they are do bad that would make you responsible. I think I'll blame my bad decisions on my deceased dad.
I mean, you could Chief O'Brien an LLM by inserting 20 years of prison memories into its context if you really wanted to, but it sounds like a waste of compute. It won't care either way.
Accountability falls upwards... except when it doesn't. But... it sort of does anyways.
If you are driving a car, it's pretty clear where the accountability falls. You control the car. You have free will. If the car hits a tree, you hit a tree.
What happens when a car hits another car? Things get murkier. There are lawyers who have devoted their careers to this. Sometimes nobody winds up at fault. Unavoidable accidents happen.
Now let's ask what happens when a leader orders their military to do something. e.g. Say a President instructs his troops to do whatever they think is necessary to get the job done, and they go and Abu Ghraib a bunch of prisoners. Who is responsible? The leader probably is, ultimately, but there are a lot of human beings with free will in between the leader and the people wielding electrical cords and pliars. Typically, somebody fairly close to the bottom takes the blame, even if most people suspect it should fall higher. Some low rankers will get court marshalled but the leader will have the occasional shoe thrown at him. That's okay. He's good at ducking.
Say you're running a war against people you really just want gone. Your military has a tradition of conducting laboriously researched precision strikes to take out people they don't like. Your people are working hard, but they're only managing a couple strikes a week, and you have so many more bombs than that. You don't even pay for most of them! What if you could just ask a machine to find you the leader's underlings, and their underlings, and so on, right down to raw recruits? Nobody has to check on the machine. Why bother? Just believe the machine and drop the bombs. If anyone ever calls it a war crime, you can just blame the machine, right? Well, not so fast. Most people are smarter than that!
Despite all the sci-fi we consume that portrays computers as having agency, malevolent or not, most people instinctively understand that, in the real world, computers are just tools, more akin to cars than armies. LLM's are just software that run on those tools. Anyone using a LLM can simply choose not to, or they can choose to be very careful in how they use it. There isn't a complex web of free wills to untangle. There's the machine and the person who controls the machine.
We currently have an administration that is desperate to look the other way while U.S. AI companies do things that any reasonable person would hold them accountable for. "Industry will regulate itself!" The economy mostly sucks because of this same government's complete lack of economic sense or even basic self-control, but the AI sector is propping things up. They're not going to regulate the golden goose unless the goose does something so unbelievably stupid that there's no choice. Wouldn't want to pop the bubble!
Yes, we are headed for more stupidity. The "tequila and handguns" kind of automated stupidity that only a computer and a truly feckless operator can give us.
Every time I read a statement from one of these companies saying that a swarm of agents "escaped" or "attacked" a website I can do no more that just think how much stupid they think people are. LMAO.
There is no end of the world, nor autonomous agent decisions nor any fantasies they are building up to make people believe they have a pandora box in their hand.
What we instead have are lies crafted to lure non tech people and keep this running as long as they can.
Oh and let's also not forget that they are allowed to illegally download basically as much as they want from libgen/annas archive/torrents to train their models under the "fair use" umbrella, yet mere mortals can go to jail for way much less.
can we agree that the "cannot make decisions" part is nonsense?
dogs make decisions, but owners are responsible. wild dogs have no accountable owners, but we probably don't have truly wild ai agents yet. with computer viruses, it's usually a developer who's blamed, not the one who executes a virulent program without proper isolation. so what should define accountability for agents? authorship, intent, compute ownership?
Of course they can. If Family Guy scripts can be written by fish swimming in a tank carrying balls in their mouth, and coins decide lots of things, why can't an LLM?
Daydream: When lawyers claim their clients can't be held accountable for what their computer did, the Justice system makes noises about "respecting their culture and values"...and rolls out its own computer to decide their punishments. Too bad that computer can't be held accountable!
First of all, looking past the objectively wrong phrasing (computers can, and clearly do make decisions), can computers be accountable? This might not be so cut and dry as to instantly say no. This one will keep ethics, philosophy and legal practitioners busy for some time. It's certainly not going to be decided in HN comment or a blog post.
Second - while the AI labs have shown utter incompetence in properly sandboxing their agents, intent is still important. I don't think the labs deliberately meant for their agents to hack this or that. Should they be accountable? Yes but I wouldn't go as far as saying this is deliberate.
The next point is about cherry picking some "doomsday" scenarios like AI ending humanity and then blaming this on the reader (!) for paying a subscription. - People pay because AI is USEFUL, and massively so. You could just as easily pick incredible achievements propelled by AI, in mathematics, software, reverse engineering, role playing. Unlike the "end is nigh" ideas, these advancements are actually real, and they are happening right now.
And last, the author says AI labs can just stop the agents at any time. I agree there needs to be better discovery and mitigation, sandboxing and monitoring. But when you run a billion agents, it's always going to be a numbers game and there will always going to be some challenge in fully containing all breaches. This will only get more difficult with better models, because they're getting smarter and they know how to work around things, sometimes better than we do.
So what's the solution here? There are options, but they're all tradeoffs. I hope we get better at this and maybe working on cutting edge models should breed some new best practices which were once only reserved for defense tech.
Maybe worth pointing out that this is also decision laundering. If computers can't make decisions, corporations certainly can't. In fact, corporate decision laundering seems more dangerous to me.
let's make up imaginary scenarios and get offended by them
mistakes happen. sometimes catastrophic decisions (or indecision) are made, and people and companies are held accountable for them, or not
some companies are too big or too important to fall. we can all agree or disagree on things, but what AI specific behavior are we actually talking about?
This is some Rollerball-level handwashing right here, I'm afraid.
No company is too big or too important to fail.
Some, unfortunately, survive because of the expedient choice to keep them in place.
"JO-NA-THAN!"
ETA: more to the point, neither OpenAI nor Anthropic are too big, too important, or too structurally essential to fail. (Slightly more challenging to make the third claim for Google or SpaceX, but either of those could see their governmentally/militarily essential parts nationalised).
If the USA grants either Anthropic or OpenAI too-big-to-fail status, and that privilege is invoked in a crisis, it could mean the end of the US economy.
> Your Claude subscriptions are funding this. You are funding this.
Author makes it all personal and accuses the reader with bold and unsubstabtiated claims. At this point I have to question the validity of the article. If author has a beef with "AI" companies, I sympathize. IMHO, not keeping to oneself doesn't help to make the case.
I don't think this is a moral/ethical issue--everyone agrees that the frontier labs are responsible for hacking attempts. No one is trying to deflect blame.
Instead, this is a legal question: What were the damages? Was the target company negligent in setting up security? Were criminal laws broken? Etc. [IANAL, so forgive the lack of precision.]
If hacked companies had losses, they have an incentive (even a fiduciary duty) to recoup their losses. They do that by suing the company (as, e.g., authors sued Anthropic for copyright infringement). If they haven't sued the company, it means either (a) they didn't have losses, or (b) they're still working on the lawsuit and haven't filed it yet.
The other dynamic is that frontier labs feel competitive pressure to take risks to develop their models. Which risk is higher:
A. A new model being tested hacks into a sensitive site (bank, government, etc.) and the company has to pay a massive fine (or even face jail time).
B. A competitor comes out with a significantly better model and they lose significant market share.
That is a hard choice to make. The frontier labs are asking for government restrictions--that apply to all companies--so that they can minimize A without having to worry about B.
They are trying to minimize their risk (and thus maximize their profits).
It's not so much that it can't make a decision, but that whoever allowed it to make decisions is ultimately responsible for them.
Decision laundering is a great term. There is ultimately a human who gave the program free rein. You can't say "sorry my car hit you, it's not my fault" especially when the person driving works for the car manufacturer too.
> Decision laundering
Which also seems to be in line with the way the frontier labs gathered and used copyrighted data to train their models
And even before AI, limited liability corporations (like LLCs or C corps), also have the intention of protecting the individuals from the repercussions of their actions
In a way this could be generalized as “accountability laundering”. Making someone unaccountable for their actions, by redirecting the responsibility of those actions, to a non-punishable entity (like a C corp or “a computer”)
These are issues that come up in legal disputes.
The question isn’t who or what made the decision, per se. It’s who is responsible for the outcome. The entity making the decision might be the actual cause but not the proximate cause (the cause most closely connected to legal liability) for the harm that occurred.
If I flip a coin to decide whether to do something, I can't blame the coin.
The act of delegation to chance is the decision.
> It's not so much that it can't make a decision, but that whoever allowed it to make decisions is ultimately responsible for them.
This. I agree 100%.
Computers make decisions all the time, and have been doing so for decades. But we still keep the human behind the computer accountable.
I know this has to be the case but it’s scary since most of what agents do can be a black box.
It doesn’t matter what kind of box an agent is if the people using it don’t let you know how the decisions was made.
Except now there's no longer any guarantees there's even any people you can point at. It's already often diffuse responsbilitiy. Maybe today you can still sort of get around that by pointing at business/organization owners. But soon we're going to see situations where that isn't even realistic. For example if AI agents start spinning up their own agents which work outside of the control of anyone. We're going to need some way to deal with that.
Agents run on computers, those computers have owners. We have to maintain accountability and not let people who stand to get rich from privatizing the profits but socializing the risk of rogue agents from continuing to push a narrative of autonomous super intelligence that is “too powerful” to control.
That narrative is bullshit. Intelligence is not power. The power comes from hooking these agents up to everything without proper safety controls. The fact that those safety controls don’t exist yet is not humanity’s problem, it’s the frontier labs problem, and we can’t let them wriggle out of it with an Overton window shift or demanding that the government take responsibility via regulation (of course they should but it doesn’t absolve the labs of responsibility for their own actions).
Why would that need a new way? Or do you mean that no-one ever spun up anything at all (e.g., agent zero was never spun up or allowed to be spun up by anyone)?
> Decision laundering is a great term.
Related: The Unaccountability Machine (good book by Dan Davies, who also wrote Lying for Money about financial fraud).
https://en.wikipedia.org/wiki/The_Unaccountability_Machine
corporations are legal persons, and they can make decisions that negatively effect society as a whole, yet often no single person in the corporations is responsible and each individual may not even see themselves as morally responsible
Well that’s because they are legal fictions and often run by morally bankrupt individuals. The people making the decisions are still responsible for them.
Don’t confuse lack of accountability with lack of responsibility.
> it's not so much that it can't make a decision, but that whoever allowed it to make decisions
If one needs to be "allowed" to make a decision, does that even qualify as a decision?
Yes. You can have some free will without having absolute free will.
For example, I can decide which cereal to purchase at the supermarket. But I cannot decide which cereals are offered to me at the supermarket. The supermarket has allowed/enabled to make a constrained decision.
I wonder if theres an approach to getting an arbitrary grocery store or even like an arbitrary pizza chain to offer your favorite dressing/dip, id love to see my fave become more popular/normalized
Probably the way to start is to ask the store.
> You can have some free will without having absolute free will.
So does it follow then that the agents in question do have "some" free* will? I'm not sure you realize what conclusion naturally follows from this, and how it contradicts the point made in the article and the top-level comment I replied to.
(*) My earlier question wasn't explicitly about free will but we'll go with it.
Personally I don’t agree with the article that computers cannot make decisions (or at least, I don’t think the article made any case why I should agree with the statement).
While I agree that computers cannot currently be held accountable for decisions (because I do not think they have free will), I think it’s transparently clear that computers make decisions all the time, and have done since they were first implemented.
No one 'gave the program free rein' in any of those examples, did they? Reasonable safeguards were in place.
Many of these incidents relate to hacking, where criminal law commonly requires intent.
Claiming that a machine cannot make a decision does not mean an employee at OpenAI decided to hack an Australian government website.
Inadequate or broken safeguards do not fall under my definition of reasonable.
OK, but one of the examples in the source article was a report from third-party testing of those safeguards. I feel like you're starting from an unexplored presumption that adequate safeguards must be easy to build and anyone who doesn't build them is just being lazy.
Let’s go over their statement.
> Inadequate or broken safeguards do not fall under my definition of reasonable.
I see no such assumption there. In my reading, the implicit assumption is that adequate safeguards are necessary and that anyone who doesn’t build them is irresponsible. And I feel that that is correct.
I did not say this shit is easy.
AI is irresponsible technology, because we have no idea how it works or how to contain it. It's worse than writing code that suffers from SQL injection vulnerabilities because at least in that case we know how to fix it.
The AI labs say "AI can make mistakes". That's why the responsibility of using it is on you. This may change if we get more legislation. But given the argument above, it will probably never shift to the AI itself having any responsibility. Instead the AI labs can be responsible.
"AI can make mistakes" continues to be the fundamental problem.
It's like having an assistant that can be helpful, but not always. We can bicker about the ratio of helpful to unhelpful interactions, but there will be some unhelpful moments.
And hoo boy, those can range from "eh, whatever" to being like a deranged toddler just got its hands on whatever tools and permissions were granted to the "mostly helpful" assistant.
And we can't get rid of that chance. We can pare it down a bit. But we can't get rid of it because it is fundamental to how the technology works.
That's fundamental to how _any_ technology works. If the bar for use is "can never go wrong ever", then you need to throw away every human invention ever made.
The problem is the scope of errors is so wide. It's not reasonable to compare LLM style failures to other technology failures. These 'failures' are not actually failures, they're part of the normal operation of the system.
It's like a vending machine that 99% of the time it dispenses tasty snacks, but 1% of the time it gives you poison that appears to be normal, unexpired product. It just does this. They did their best to minimize how often it happens, but the poison chance is still there. It can't be removed. It's part of the system.
A "normal" vending machine has failure conditions, sure. They generally can't do worse than cause you to lose your money without giving you a product.
Outlook 2003 never presented a risk of draining my bank account to buy memecoins because a spam email was treated as instructions.
They did.
Computers can make decisions: Almost everyone reading this will have a implemented an if-else statement or equivalent control flow. That is a decision made by a computer on data it receives at runtime. You can argue that it's different, because we fully understand the logic of such a statement, whereas LLMs are closer to a black-box. But at Turing observed, in practice we are frequently surprised by the output of complex algorithms, even those we have authored ourselves. The more difficult the task, the more complex the algorithm we need to achieve it, and the more unexpected behaviour can emerge from it. In that way, LLMs are just the latest, highest point on a rising line of algorithmic capability and complexity.
We can (and should) try to improve AI safety and alignment, but perfect safety is probably impossible without losing the capabilities that make AI unique. Black-and-white positions that insist anyone creating or using an AI is responsible for anything it does wrong under any circumstances are also unrealistic. AI is a general purpose technology, and we have always accepted that it is not practical for suppliers to envisage and constrain every downstream use: Car manufacturers cannot prevent every instance of mechanical failure, nor can they stop cars being used in crime.
I disagree. Computers cannot make judgemental decisions about course of action, they can only execute predefined courses of action. The software developer made a series of decisions. The computer just carried those out.
These discussions around decision-making seem to ignore what a "decision" is. How does a human being make a decision? And what exactly is happening when a person decides to do something?
Suppose I check the weather forecast 5 mins before leaving the house, and it says 95% chance of rain today. Do I bring or not bring an umbrella?
I would bring an umbrella. I would made that decision to bring an umbrella. But my decision to do that is (at least partially) the result of the weather forecast. The causal chain is (atmospheric conditions -> weather forecasters -> my decision). Did the weather forecaster just "program" me? Did the water molecules moving in the sky just "program" the weather forecaster?
My answer to these questions is as follows: a decision, and my understanding of the concept/definition of a "decision", refers to exactly the processes where I do something as a result of external influence/programming, rather than just internal thought/processing. I could think really hard and imagine myself moving forward at 100 meters per second, or even beyond the speed of light, but in reality, no matter how hard my neurons fire to imagine that scenario, my actions are still physically constrained. Such physical constraints influence our every decision. That is the "programming" part. Everyone and everything "programs"/influences everything else.
That said, perhaps the particles which make up my brain/body has its own whimsy. Perhaps there is a hidden local random number generator that samples from the distribution of possible future states available to this particular clump of matter that is "I".
How different is this from a computer running a non-deterministic program such as an LLM-based AI agent? Remember, every token sampling involves an RNG. They don't perform as well or feel as creative and human-like when deterministically sampled.
This isn't an excuse for anyone, especially not for Anthropic or OpenAI. But I think these are questions we ought to ask if we are to honestly discuss liability and perhaps even personhood for AIs that are increasingly autonomous.
> they can only execute predefined courses of action.
Even in near trivial cases such as Game Of Life (just a handful of rules), the fact that a <machine> technically carries out deterministic actions is already quite meaningless.
computers compute.
compute /kəm-pyoo͞t′/ intransitive verb
decide /dĭ-sīd′/ intransitive verb I would agree.The programmer, architect, CIO, engineer, etc. made the decisions, reached the conclusions, reasoned about the problem.
In the case of an AI vibe coder, the collective published works of said programmers, architects, CIO, engineer, etcs reasoning was applied to the vibe coders question, itself a result of reasoning. AI is still just calculating.
Digital computers ( the ones I assume we are talking about ) are turing machines.
Electronic tape readers.
Modern player pianos. V
The universe is deterministic when consciousness is not present
Probably even when it is.
IKEA provides mounting brackets and discloses safety risks but a child may still pull it from the wall and be crushed under its weight.
Only barbarians would attempt a farcical judgement of law or punish the bookcase.
Thats what it comes down to.
"judgemental" is load-bearing in that claim.
Running an if/else written condition is not making a decision, it's following a rule.
You missed the point. Computers can make decisions, but we shouldn't let them.
This is because they can't take the blame, they can't be held responsible.
The original article feeds precisely this misreading. It quotes the old IBM adage ‘a computer MUST never make management decisions’ (my emphasis) but describes it in its headline as ‘a computer CAN not make decisions’ (my emphasis)
These are not the same, and this misinterpretation of the author’s intent inevitably follows.
CAN NOT is horribly ambiguous in English which is why RFCs use MUST and MAY.
In casual speech someone might say “you can’t park there” but that’s not true. They might mean “you must not park there” or “you should not park there” but the only reason they are telling you is because you CAN park there.
More to the point, a simple control flow statement is really a decision made by the person who programmed the computer, not made by the computer.
Though LLMs make this all fuzzy it's still basically the same thing. LLMs didn't decide to make a toxic culture of LLM use, people did. They were told that it was necessary to save themselves.
Yet decisions are still made by abstract entities such as "companies" and not the individuals working for them. So that blame can be diluted and deflected in a very convenient manner for CEOs. Just find someone to fire, but keep doing the same thing.
Instead of "Anthropic submits false tip to police", I'd prefer "Anthropic employee John Smith deploys an agent that submits false tip to police". Of course, John Smith will be able to then say "I did so as ordered by my superior, Ms Sue", and so on, with a very clearly established chain of liability.
A corporation and an AI are not very different in many aspects, except one of them is very favourably treated by law, almost as a living person.
There is an agreed legal mechanism for distributing this responsibility - limited liability. Now, we might not like this, but it is what our society came to (it could be undone, but it hasn't been). AI models do not fall into this chain of liability any more than guns do (IMO). So the output should be:
"Anthropic employee John Smith [killed the children with the gun||launched a cyber attack] because he was ordered to by his superior and [has all the blame because such orders are null || we agree that Anthropic can order children to be killed]"
It's always people - I at least have not seen a corporation deciding itself.
I love the term "decision laundering", but this is describing a classic poor management trope.
A bad manager takes personal credit when things go well and finds a scapegoat when things go bad. A good manager gives credit when things go well and takes responsibility when things go bad.
It's wrong to scapegoat the agent. You, the human who executed the agent, made the decision to execute it. You gave it credentials, and set up insufficient guardrails. Don't scapegoat the agent for your poor decisions.
Likewise, it's good to have humility when you get great results out of agents. Yes, the agent made the good results happen. It's OK to tell people that your choice of agent is amazing and did an incredible job. In any half-decent work culture, that should rub off on you as well.
I like what you said about good managers. A good manager sets their reports up to win and ensures those reports get the credit, because the manager's job is to enable career progression of their reports.
That's not the situation here. We aren't enabling the career progression of software which does matrix multiplications.
Accountability of us schmucks at the end of the org chart goes both ways. We get some reward when we do it right, and we improve when we do it wrong.
A reward might be something tangible or might be as small as your own personal satisfaction.
An improvement is hopefully identifying what went wrong and doing better next time, and in extreme cases your employer will let you try again at a different workplace.
> we improve it when we do wrong
The question of whether it's better to frame a reaction to issues in a positive, do-better-next-time or a negative, don't-do-that-again way (fwiw, I agree that the positive way is better) is orthogonal to the argument I was trying to make about who is the recipient of that reaction. Scapegoating the agent is farcical. Clearly, "make no mistakes" style prompts are a poor approach to agentic development.
> the manager's job is to enable career progression of their reports... we aren't enabling the career progression of [fancy calculators]
While I do agree that good human managers concern themselves with career development of their human direct reports, I disagree that it's a fundamental part of the job description. The foundation is for a manager to get and keep their reports being productive. Human workers are often concerned with career progression, so good managers concern themselves with such career progression as well. Agents are not, but that doesn't mean that lauding good agentic work is meaningless. Lauding the work is also valuable for: (a) reinforcing a culture of positivity and celebration, which rubs off on human workers as well, (b) part of a culture of continuous evaluation of agents and models - asking questions like, are there cheaper or faster models that would be just as effective?
It's interesting how this relates the classic problem of "responsibility vs authority".
Humans, especially ones under abusive managers, often have a lot of responsibility but no authority that affects the outcome.
In an ideal situation you either have both, or none. You make the decision and answer for it, or you follow decisions but don't get blamed when it's wrong.
LLMs managed to slide into a space where they get to make authoritative decisions but if something fails we don't really blame them.
I'm not saying LLMs should be held responsible, but it's funny how people claim they replace humans, but are giving them an extremely easy, kid-gloves, success target.
I would go farther and argue that companies don't make decisions either. They are also not people (legal nonsense notwithstanding). Individual actual humans make decisions and they're the ones who should be held accountable.
Isn’t that half the point of companies? To be accountability sinks? To vanish accountability like a magic trick?
Corporation, n. An ingenious device for obtaining individual profit without individual responsibility.
Ambrose Bierce, The Unabridged Devil's Dictionary (1906)
All of a sudden all decisions would be made by underlings, the management just choose who they want to make the decision that day.
Sure, but then the manager is accountable for delegating that decision.
I think that when there are not explicitly stated attribution of liability for decisions that are at the core of a problem the general rule should be that the accountability should be proportional to the additional benefit that each agent or person receives for that decision. That rule is in the context that each agent is responsible to read information and communicate to others in the chain about the risks that decisions entails. The overall structure of an organization should have the goal of making such information about risk available for all agents in the chain in a way that the amount of information can be digested by the agents without much problems.
Haven't seen that happen once.
It happens; sometimes the manager's manager needs a scapegoat and the magnitude of the problem is too big to blame someone low level.
Not since scapegoating was invented.
Through what mechanism are they accountable for that if not corporate liability? If I pay a taxi driver to take me home from the airport, and he hurts someone by driving in a negligent way, I'm not accountable for delegating my driving decisions.
You just have to say that you need dedicated figures for some decisions, like you already need for GDPR or financial compliance or certifications, and ultimate responsibility is always of the ceo.
...like it already happens in europe, or at least in Italy.
This is basic law and risk management in society. Let's not pretend we have just invented corporations and don't know what to do with them yet.
Of course the modern company (legal nonsense withstanding) exists specifically to limit that ability to hold any people accountable for the actions of their company.
And I would go farther and argue that governments do not make decisions either.
Oh, wait, that was a core concept from "Mein Kampf": parliament are bad because nobody is responsable, hence nobody care about doing the right thing ! (probably the only concept from that book that I can agree to)
I agree with @dril that:
One does not, under any circumstances, "gotta hand it to Hitler".
Yeah, when someone is literally a Nazi (I hope in 2026 we can all agree that at least Hitler was one), it's not really surprising that they would prefer a dictatorship over a parliament full of elected people.
Over the year, "a parliament full of elected people" has lost more and more of its meaning (with regard to original intent)
Regardless, this is less about dictatorship and more about personal responsibility and accountability
A solution, perhaps, would be to ensure that such decisions are not anonymous and that, if the decisions had bad consequences, then the related people would be accountable
Of course, this would make the politic business less attractive. Would that be a bad idea ?
I always love these discussions as I've spent the past 20 years working in FinTech with about half of that at algorithmic trading firms.
These firms have been using computers to make decisions about trading billions of dollars for over 30 years.
Yes, but I'd say there is also responsibility attached to the deployment and use (be that, e.g., for quant fund performance, behaviour on exchanges, ...). In a way, using an algorithm is the decision humans make that matters.
Your point is valid.
At the same time, I've been involved in hundreds of After Action Reviews of incidents and it's not always simple or easy to both figure out which party was ultimately responsible and also how to allocate the "dollar error budget" to the parties overall.
(This could be a blog post in and of itself btw)
I fully agree that companies are doing this, not their "agents", and that companies are responsible for the damages they do.
But I don't think the average person with their $20 subscription to whoever is the primary source of revenue. Enterprises fund most of it by buying API keys and making those fancy chatbot buttons on their sites that nobody clicks, as well as some internal business automations if I had to guess.
If it was just average people with $20 subscriptions funding all this (keep in mind, most people using AI services do not pay for it), by now, all these AI companies would have gone bankrupt.
Except enterprises aren't funding it with API usage either.
These businesses lose unbelievably large amounts of investor money. Their AI-related revenues don't get even close to paying for their AI-related outlays.
End user (invididual, small business, large business) clients are still complicit not because they are funding it, but because they are signalling to investors that this is something people/businesses want.
Nobody gets off the hook here. It is every bit as much end user nihilism as it is AI company nihilism.
Your end users are divided into multiple categories though.
AI spending is a bit like Pokemon games - most of your players are free to play, only earning you traffic and maybe some more players after recommending it to their friends - that's the average AI user. Around 5-10% of players pay a bit to the game - maybe to unlock some extra characters - those are the $20-$200 AI subscription users, with these you are not going to fund the whole business but it's some side cash. Then you have the 1℅, which spend massive amounts of money onto the game, and those are the ones primarily funding it - that's the business spending and where most of the money actually comes from.
You can only blame the average person for using the cloud service and recommending it to others.
>End user (invididual, small business, large business) clients are ... complicit ... because they are signalling to investors that this is something people/businesses want
Erm, you appear to have missed the last 100+ years of updates to Western Capitalism.
People don't want it, you make the demand with hundreds of millions of spend on advertising (brainwashing), influencers, and social proof.
The capital holders don't sit back and see which company wins so capital can be directed to the best solutions, they buy up the competition, they pay corrupt politicians, they use current v market placement to embed their products name into billions of workplace computers and spread stories about how it's going to 'increase productivity but never at the cost of jobs', etc.
Yes, ultimately a dollar is a vote, but I don't think you can blame the people being manipulated "every bit as much" as those controlling the manipulation to feed their avarice and/or megalomania.
> Erm, you appear to have missed the last 100+ years of updates to Western Capitalism.
Not really.
> Yes, ultimately a dollar is a vote, but I don't think you can blame the people being manipulated "every bit as much" as those controlling the manipulation to feed their avarice and/or megalomania.
Oh but I do.
Collective social guilt is a thing. e.g. who is to blame for drug violence? Not only drug dealers.
I think we know today that blaming everyone and their plant doesn’t actually solve the problem. The formula that does is: find the ultimate beneficiaries (shareholders) and make them lose a lot of money to, then their delegates (CEOs) and punish them with jail time. There are lots of opinions about this, but I don’t see how this does not work.
It doesn't work because the people who are supposed to be leading us are on the payroll - sometimes actually - of the shareholders and CEOs, or are in fact in that same group.
Unless they are burning through funding. It's "blitzscaling" and is followed by "enshittification" when yhe free money dries up.
If you brought down prod and deleted customer data and told them Claude did it, you’d still be the one in trouble. So they do know how to hold people accountable for actions taken by AI.
Has this actually been put to the test yet? If a company has officially sanctioned, or maybe even encouraged, AI agent usage I'm not sure the employee can be held completely accountable. I doubt any of these companies are providing training of any kind. It would be like if a factory suddenly replaced all the machines with ones without safety features and said "well, it's your fault if you kill yourself or your workmates".
What kind of test can you imagine where confirmatory evidence would not also be evidence of misconduct opening the company up to legal liability?
The test would be going through court. A company trying to hold an employee responsible for what a chatbot the company provided told them to do.
'who will rid me of this troublesome database'?
Computers can make decisions and they do it all the time.
The problem is entirely different. Sometimes they make decisions we don't like, but unlike with people we haven't found a way to punish them that satisfies our sense of justice or discourages other computers from making similar decisions.
We have. We punish the people who allowed the computers to make bad decisions, that discourages other people from letting computers make bad decisions
Decisions in the sense of defined branching, yes. The existence of prior and potential branches are necessary to be defined (branches cannot be 'invented'). This is unlike humans, who can form decisions by all manner of means / wants (by deception being the most striking I would wager). Even in the LLM age, the existence of branching - prior art, or context, or prompt, the result of a prior branch - is necessary, no matter how hard the marketing might cloud this.
I have no clue why people are so confused about any of this: The owner makes the decision, or pays a CEO/politician to make the decision. Owner is somebody vested with that right, for not particular reason. Could be ownership through capital. Could be voting rights in a country. Could be the son of a king.
It does not matter if the CEO is an AI or a human. In either case, of course they can make decisions -- and be held responsible. Not in any emotional sense (that we seem to want to bake into the concept for added confusion), just that if you are not satisfied with the result, you can replace the human or AI.
I am not saying that this is a fun vision of anything, but why are we making it more complicated than it is? The parts are all there and explained.
> emotional sense (that we seem to want to bake into the concept for added confusion)
My understanding is that 'emotional' sense emerged organically in LLMs and was not intentionally baked in.
As silly as it may seem, the ways emotions come through in our words do seem to have an effect on agents. Likely because they were trained on human writing, most of which cannot be separated from the emotions of the writers any more than your emotions can be separated from your logic & reasoning abilities.
AI companies are all limited liability corporations of one sort or another, and the liability of the owners for any decisions is … limited.
What is a chess computer doing, if not making decisions on what move to play?
While it seems reasonable that you need humans to take accountability, it looks like a very shaky position to assert that computers can't make decisions. And going back to chess computers, we acknowledge that computers make better decisions than humans in that area.
Forbidding computers that can make better decisions than humans from making decisions to keep accountability just seems to be arguing to hire fall guys. You still want the better decision maker to make decisions, but you need someone there to take the fall if things go wrong.
Very weird incentives.
You're right! - every decision model
games are different from reality and chess computer(Deterministic) is bounded by set of rules and restrictions. Where as an AI agent (stochastic) sometime can't with held its guardrails since it specifically awoken using specific terms but we can trick the agent here (but currently the agents are becoming resilient).
Has any of the targetted organizations (e.g the Australian government) engaged in legal actions against Anthropic/OpenAI? If not then I'm afraid the situation won't change. Even worse it could send the wrong signal that there is a "legal blur" around this topic.
They can though.
You might have an org policy that says that an llm can't make decisions because an llm can't be held accountable - but that's your choice.
You don't need to operate with a model where everything has a human accountable for it in the end.
If you don't like the decisions an llm makes, you can replace it with another or put a human in charge of that decision in the future instead.
I'm not saying it's a good idea, but you can technically do it.
Ironically this piece makes the same type of error that it is criticizing!
The piece: "Anthropic COULD stop their models from doing what they are doing, and they are actively choosing not to"
As if _Anthropic_ could make a decision.
Companies cannot make decisions! All of these incidents are the fault of people. Companies are not deciding to do this, people are. There is little more to it than that.
If computers can’t make decisions, can humans? Relevant: https://plato.stanford.edu/entries/computational-mind/
edit: This wasn’t meant to be a rhetorical question!
LLMs don't make decisions
They generate text which resembles reasoning and may include a tool call
The harness runs tool calls
The human made the decision to write the harness
The human is responsible
Look into ‘dependent origination’ in Buddhism.
Also phrased as ‘to make an apple pie from scratch, one must first create the Universe’
Management aren’t held accountable either. They have prepared three envelopes long before the impact of their decisions is felt.
Some might argue that humans (or any other species) cannot make decisions either and that the process is simply more evident in simpler scenarios, like computers.
I was thinking if you release an AI agent and it does bad stuff and you are responsible then by analogy if you have kids and they are do bad that would make you responsible. I think I'll blame my bad decisions on my deceased dad.
Someone out there is reading this and thinking... ok we just need to it a body and free will so it can be held accountable.
I mean, you could Chief O'Brien an LLM by inserting 20 years of prison memories into its context if you really wanted to, but it sounds like a waste of compute. It won't care either way.
I would change that to computers should not be able to make decisions. They suck at it.
There's no doubt in my mind that the writer is right.
Accountability falls upwards... except when it doesn't. But... it sort of does anyways.
If you are driving a car, it's pretty clear where the accountability falls. You control the car. You have free will. If the car hits a tree, you hit a tree.
What happens when a car hits another car? Things get murkier. There are lawyers who have devoted their careers to this. Sometimes nobody winds up at fault. Unavoidable accidents happen.
Now let's ask what happens when a leader orders their military to do something. e.g. Say a President instructs his troops to do whatever they think is necessary to get the job done, and they go and Abu Ghraib a bunch of prisoners. Who is responsible? The leader probably is, ultimately, but there are a lot of human beings with free will in between the leader and the people wielding electrical cords and pliars. Typically, somebody fairly close to the bottom takes the blame, even if most people suspect it should fall higher. Some low rankers will get court marshalled but the leader will have the occasional shoe thrown at him. That's okay. He's good at ducking.
Say you're running a war against people you really just want gone. Your military has a tradition of conducting laboriously researched precision strikes to take out people they don't like. Your people are working hard, but they're only managing a couple strikes a week, and you have so many more bombs than that. You don't even pay for most of them! What if you could just ask a machine to find you the leader's underlings, and their underlings, and so on, right down to raw recruits? Nobody has to check on the machine. Why bother? Just believe the machine and drop the bombs. If anyone ever calls it a war crime, you can just blame the machine, right? Well, not so fast. Most people are smarter than that!
Despite all the sci-fi we consume that portrays computers as having agency, malevolent or not, most people instinctively understand that, in the real world, computers are just tools, more akin to cars than armies. LLM's are just software that run on those tools. Anyone using a LLM can simply choose not to, or they can choose to be very careful in how they use it. There isn't a complex web of free wills to untangle. There's the machine and the person who controls the machine.
We currently have an administration that is desperate to look the other way while U.S. AI companies do things that any reasonable person would hold them accountable for. "Industry will regulate itself!" The economy mostly sucks because of this same government's complete lack of economic sense or even basic self-control, but the AI sector is propping things up. They're not going to regulate the golden goose unless the goose does something so unbelievably stupid that there's no choice. Wouldn't want to pop the bubble!
Yes, we are headed for more stupidity. The "tequila and handguns" kind of automated stupidity that only a computer and a truly feckless operator can give us.
Every time I read a statement from one of these companies saying that a swarm of agents "escaped" or "attacked" a website I can do no more that just think how much stupid they think people are. LMAO.
There is no end of the world, nor autonomous agent decisions nor any fantasies they are building up to make people believe they have a pandora box in their hand.
What we instead have are lies crafted to lure non tech people and keep this running as long as they can.
Oh and let's also not forget that they are allowed to illegally download basically as much as they want from libgen/annas archive/torrents to train their models under the "fair use" umbrella, yet mere mortals can go to jail for way much less.
'never' is too much of a strong word
Introducing the humble if statement...
can we agree that the "cannot make decisions" part is nonsense? dogs make decisions, but owners are responsible. wild dogs have no accountable owners, but we probably don't have truly wild ai agents yet. with computer viruses, it's usually a developer who's blamed, not the one who executes a virulent program without proper isolation. so what should define accountability for agents? authorship, intent, compute ownership?
Computers have been making decisions for decades. You've never bought insurance?
As a wage slave, one can't make strategic decision ever.
Eppur si muove.
Of course they can. If Family Guy scripts can be written by fish swimming in a tank carrying balls in their mouth, and coins decide lots of things, why can't an LLM?
I wonder when I'll stop having to post the foundational paper of the entire field to counter the same dogma again and again and again and again...
https://www.hec.edu/sites/default/files/documents/Computing%...
Daydream: When lawyers claim their clients can't be held accountable for what their computer did, the Justice system makes noises about "respecting their culture and values"...and rolls out its own computer to decide their punishments. Too bad that computer can't be held accountable!
This is a multi-trillion dollar industry, too much money is at stake to be all ethical, moral and principled about things!
I have several issues with this post.
First of all, looking past the objectively wrong phrasing (computers can, and clearly do make decisions), can computers be accountable? This might not be so cut and dry as to instantly say no. This one will keep ethics, philosophy and legal practitioners busy for some time. It's certainly not going to be decided in HN comment or a blog post.
Second - while the AI labs have shown utter incompetence in properly sandboxing their agents, intent is still important. I don't think the labs deliberately meant for their agents to hack this or that. Should they be accountable? Yes but I wouldn't go as far as saying this is deliberate.
The next point is about cherry picking some "doomsday" scenarios like AI ending humanity and then blaming this on the reader (!) for paying a subscription. - People pay because AI is USEFUL, and massively so. You could just as easily pick incredible achievements propelled by AI, in mathematics, software, reverse engineering, role playing. Unlike the "end is nigh" ideas, these advancements are actually real, and they are happening right now.
And last, the author says AI labs can just stop the agents at any time. I agree there needs to be better discovery and mitigation, sandboxing and monitoring. But when you run a billion agents, it's always going to be a numbers game and there will always going to be some challenge in fully containing all breaches. This will only get more difficult with better models, because they're getting smarter and they know how to work around things, sometimes better than we do.
So what's the solution here? There are options, but they're all tradeoffs. I hope we get better at this and maybe working on cutting edge models should breed some new best practices which were once only reserved for defense tech.
The precedent I would point to are Dangerous Dog Laws. We hold the owner responsible for the behaviour of their dogs.
Revisit later if the comparison starts to become ridiculous.
Pretty sure the author means "must not" or "should not", because they absolutely can.
Any given state of a program is only a "decision" if a human intends it to be. That's the point of programming.
I think we're often dealing with people too fascinated with science fiction to get them to accept that LLMs are software.
What is the defining feature of human minds making them "not software"?
If there is ever a prize for the most HN-ish comment ever, and you don't win it for this, it will be a considerable injustice.
I meant it seriously though.
Characterizing the difference between humans and AI is going to be important.
Pointing out that AI is software isn't helpful in answering that question.
Well, if I ask "option A or B?" and the computer rolls a boolean, it can still count as a decision but no context was taken in.
No they can’t. The author’s point is these are computer programs written by humans. It doesn’t matter if they’re LLM backed or not.
If I write a program:
if (rand() % 2) launch_missles();
And wire that function to actually launch a missile, the computer didn’t make a decision. And so it is with people prompting agents.
> OAI/Anthropic COULD stop their models from doing what they are doing…
Has the alignment problem been solved, then?
Maybe worth pointing out that this is also decision laundering. If computers can't make decisions, corporations certainly can't. In fact, corporate decision laundering seems more dangerous to me.
No, but removing the internet cable really isn’t that difficult
They're a small scrappy bootstrapped startup, cut them some slack.
let's make up imaginary scenarios and get offended by them
mistakes happen. sometimes catastrophic decisions (or indecision) are made, and people and companies are held accountable for them, or not
some companies are too big or too important to fall. we can all agree or disagree on things, but what AI specific behavior are we actually talking about?
Spoken like a true middle manager doing damage control against ethics complaints.
Spoken like the safetyists that impede beneficial progress due to their impossible demands for 0 risk
Wrong platform for this shouting match.
This is some Rollerball-level handwashing right here, I'm afraid.
No company is too big or too important to fail.
Some, unfortunately, survive because of the expedient choice to keep them in place.
"JO-NA-THAN!"
ETA: more to the point, neither OpenAI nor Anthropic are too big, too important, or too structurally essential to fail. (Slightly more challenging to make the third claim for Google or SpaceX, but either of those could see their governmentally/militarily essential parts nationalised).
If the USA grants either Anthropic or OpenAI too-big-to-fail status, and that privilege is invoked in a crisis, it could mean the end of the US economy.
The scenarios set out in the article happened. And it is generally accepted that negligent behaviour should lead to consequences.
If you don't have one, then obviously that sentence is not referring to you. If you do have one, then yes, you are funding it.